Privacy policy
Grami is a meal tracker. It needs your meals to work — and nothing else. This page says exactly what is stored, who touches it, and how to get rid of it.
Last updated 9 September 2026
Who we are
Grami is built and operated by Softlance (Euvoia, Greece), the data controller for the personal data described here. For anything on this page, write to info@softlance.dev.
What Grami stores
| Data | Why |
|---|---|
| Email address and password (stored hashed) | To create your account and keep your history across devices and reinstalls. |
| Meals: photo, description, calories, protein, carbs, fat, fiber, sugar, weight, meal type, date and time, favourites | This is the product. It is what your Today screen, history and progress charts are made of. |
| Optional profile: first name, last name, age, weight, daily nutrition goals | Only what you choose to type in, used to personalise your targets. Leave it blank and Grami uses standard daily values. |
| Preferences: app language, notification settings | So the app behaves the same on every device you sign in on. |
Grami contains no advertising, no analytics SDK and no third-party tracker. There is no profile of your behaviour built anywhere, and nothing is sold or shared for marketing.
Who processes it
- Supabase — hosting, database, authentication and photo storage, on servers in the European Union. Your rows are protected by row-level security, so one account cannot read another's data.
- OpenAI — the meal photo, or the text you dictated or typed, is sent for analysis and comes back as nutrition numbers. It is sent through our own server function via a business API account, is used only to answer that one request, and is not used to train models.
- Open Food Facts — when you scan a barcode, the barcode number alone is looked up in this public food database. No account information is sent with it.
- Apple and Google — app distribution. They provide the store account and download, and never receive your meal data from us.
Photos
Meal photos are stored in a private bucket tied to your account and are served to your device through short-lived signed links. Deleting a meal deletes its photo. Photos you take for a meal you never save are removed automatically.
Voice and camera
Dictation uses your phone's own speech recognition (Apple on iOS, Google on Android) under the permission you granted; Grami receives the resulting text and sends only that for analysis. The camera is used only while you are photographing a meal or scanning a barcode. You can revoke either permission in your phone's settings at any time.
Notifications
Daily summaries and reminders are scheduled on your device. There is no push server and no notification content leaves your phone.
How long it is kept
Meals are kept until you delete them or delete your account. Deleting your account removes your meals, photos, profile and login immediately from the live system; residual copies in encrypted backups age out within 30 days. See how to delete your account.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, receive it in a portable format, restrict or object to processing, and withdraw consent. Most of this is immediate inside the app; for anything else, email info@softlance.dev and we will answer within 30 days. You may also complain to the Hellenic Data Protection Authority.
Legal basis
- Contract — your account and the meals you log; without them the app cannot function.
- Consent — camera, microphone and notification permissions, each revocable in your phone settings.
- Legitimate interest — keeping the service secure and preventing abuse.
Children
Grami is not intended for people under 16, and we do not knowingly collect their data.
Changes
If this policy changes materially, the date at the top changes and the app will tell you. Continuing to use Grami after a change means the updated policy applies.